VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,607)

page 37 of 2,331
  • CVE-2023-6033HigDec 1, 2023
    risk 0.57cvss 8.7epss 0.01

    Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.

  • CVE-2023-26222HigNov 14, 2023
    risk 0.57cvss 8.7epss 0.00

    The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system.…

  • CVE-2023-46238HigOct 26, 2023
    risk 0.57cvss 8.7epss 0.00

    ZITADEL is an identity infrastructure management system. ZITADEL users can upload their own avatar image using various image types including SVG. SVG can include scripts, such as javascript, which can be executed during rendering. Due to a missing security header, an attacker…

  • CVE-2023-41895HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically…

  • CVE-2023-38219HigOct 13, 2023
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into…

  • CVE-2023-0829HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Plesk 17.0 through 18.0.31 version, is vulnerable to a Cross-Site Scripting. A malicious subscription owner (either a customer or an additional user), can fully compromise the server if an administrator visits a certain page in Plesk related to the malicious subscription.

  • CVE-2023-39370HigSep 3, 2023
    risk 0.57cvss 8.8epss 0.00

    StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)

  • CVE-2023-39369HigSep 3, 2023
    risk 0.57cvss 8.8epss 0.00

    StarTrinity Softswitch version 2023-02-16 - Multiple Reflected XSS (CWE-79)

  • CVE-2023-37221HigSep 3, 2023
    risk 0.57cvss 8.8epss 0.00

    7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').

  • CVE-2023-4296HigAug 29, 2023
    risk 0.57cvss 8.8epss 0.01

    ​If an attacker tricks an admin user of PTC Codebeamer into clicking on a malicious link, it may allow the attacker to inject arbitrary code to be executed in the browser on the target device.

  • CVE-2023-33159HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2023-29347HigJul 11, 2023
    risk 0.57cvss 8.7epss 0.02

    Windows Admin Center Spoofing Vulnerability

  • CVE-2023-2072HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.01

    The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on…

  • CVE-2023-36390HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36389HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36386HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2021-42083HigJul 10, 2023
    risk 0.57cvss 8.7epss 0.01

    An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * …

  • CVE-2023-35971HigJul 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in…

  • CVE-2023-36345HigJun 23, 2023
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.

  • CVE-2023-34088HigMay 31, 2023
    risk 0.57cvss 8.7epss 0.00

    Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an…